Skip to main content

How Wayfinder Protects PHI in RFPs

How Wayfinder's two-pass PHI scanning system works to prevent protected health information from being shared with providers through RFPs.

Updated today

Wayfinder includes built-in safeguards to help prevent Protected Health Information (PHI) from being accidentally shared with providers through RFPs.

Two-Pass PHI Scanning

Every RFP goes through two automated scans before it reaches providers:

Pass 1: CM warning at submission

When you submit an RFP, Wayfinder immediately scans the visible fields for potential PHI using medical AI detection. If anything is flagged, you'll see a warning that lists the specific terms detected. At that point you can:

  • Edit the RFP to remove or rephrase the flagged content, or

  • Confirm and proceed if you've reviewed the warning and understand the risk

Pass 2: Pre-distribution scan

A second AI-based scan runs automatically after submission β€” before the RFP is distributed to providers. This is designed to catch any accidental PHI leakage that the first pass may have missed.

What Counts as PHI

PHI includes any information that could identify a client in combination with their health data β€” such as full names, dates of birth, Medicaid IDs, exact addresses, or other identifying details. Wayfinder's RFP fields are structured to avoid collecting this information, but the scanning system acts as a safety net for free-text fields where it could be inadvertently entered.

Best Practice

Avoid entering client names, ID numbers, or exact addresses in any free-text field on the RFP. Describe the client's needs and preferences without including information that could identify them.

Did this answer your question?